← CertOwl Blog

Security+

Security+ domains: what the five sections cover

By SunTzu, founder of CertOwl Published 3 min read

Quick answer

CompTIA Security+ (SY0-701) has five domains. Security Operations is the largest at 28 percent, followed by Threats, Vulnerabilities and Mitigations at 22, Security Program Management and Oversight at 20, Security Architecture at 18 and General Security Concepts at 12. The percentages describe exam weight, so they are also a ready-made map for dividing your study time.

Exam code SY0-701Domains 5Largest Security Operations at 28 percentSmallest General Security Concepts at 12 percentOperations plus Threats half the exam

What is Security+ really made of? The objectives document answers in five headings, each with a percentage attached, and those ten numbers are the most useful planning tool CompTIA gives you. They tell you what the exam thinks matters, which is not always what your course spends its time on. This article walks through the five SY0-701 domains, what lives inside each one, and how to turn the weights into a study plan instead of trivia.

The five domains at a glance

DomainWeight
1.0 General Security Concepts12%
2.0 Threats, Vulnerabilities and Mitigations22%
3.0 Security Architecture18%
4.0 Security Operations28%
5.0 Security Program Management and Oversight20%

Add the top two and you get the headline: Security Operations and Threats, Vulnerabilities and Mitigations together carry half the exam. How the exam delivers those questions, including the interactive ones, is covered in our SY0-701 exam guide.

What each domain covers

General Security Concepts (12%) is the vocabulary layer: the CIA triad, authentication and authorization, zero trust, cryptographic basics and the categories of security controls. Small on paper, but every other domain builds on it without saying so. It is the one part of the exam where pure definition questions still show up.

Threats, Vulnerabilities and Mitigations (22%) is the attacker's-eye domain: threat actors and their motivations, phishing and social engineering, malware families, application and network attacks, and the mitigations that answer each one. Most scenario questions that begin with "an attacker" are drawing from here.

Security Architecture (18%) covers how systems are built to resist attack: cloud and on-premises models, network segmentation, zero trust architecture, resilience, backups and the security of data in its different states. Expect comparisons, which design fits which requirement, rather than raw definitions.

Security Operations (28%) is the biggest domain and the most hands-on: hardening, monitoring and alerting, log analysis, identity and access management in practice, vulnerability management, automation and incident response. This is also where the material overlaps most with performance-based questions, the interactive tasks we break down in our PBQ guide.

Security Program Management and Oversight (20%) is the governance layer: policies and standards, risk management, third-party risk, compliance, audits and security awareness. Candidates from technical backgrounds consistently call this the surprise of the exam, because it is larger than three of the four technical domains.

Turning weights into a study plan

The percentages are exam weight, so the lazy translation works: give Operations the most calendar time, Threats next, and do not let Governance become the thing you skim in the final week, because a fifth of the exam is too big to donate. The reverse warning also holds. General Security Concepts is only 12 percent as a domain, but its ideas are load-bearing for everything else, so learn it first and learn it properly, just do not camp there for a month.

One thing the weights cannot do is tell you how many questions you can afford to miss in each area. Scoring is scaled, questions are weighted invisibly, and the pass mark is 750 on a 100 to 900 scale, a system we unpack in what the passing score really means. The weights guide your preparation, not your exam-day arithmetic.

A sensible sequence for most people: concepts first, then threats, then architecture, then operations, then governance, with the last two weeks spent mixing all five instead of finishing one at a time. Spaced repetition across the whole objective list beats five tidy blocks that fade in order.

Test yourself: 3 quick questions

During quantitative analysis, one estimates what PERCENTAGE of an asset's value would be lost if a certain threat materializes once. What is this percentage called?

The exposure factor (EF) is the percentage of an asset's value that is lost in a single incident (e.g. 0.5 means the loss of half the value). ARO is the number of expected occurrences per year, AV is the monetary value of the asset, and ALE is the annualized loss expectancy.

An attacker compromises the website of a professional association regularly visited by employees of a targeted company and places an exploit kit on it. What is this attack called?

A watering hole attack compromises a legitimate site that the target group visits anyway, so the victims come to the exploit themselves. Typosquatting registers domains similar to legitimate ones and waits for typos, pharming redirects traffic by manipulating DNS resolution, and spear phishing is a targeted malicious email, not the compromise of someone else's site.

An employee from marketing has administrator rights on the database server even though they are not needed for the job. Which security principle has been violated?

Least privilege requires that a user has only the privileges necessary for their work tasks, which is clearly not the case here. Separation of duties prevents a single person from completing a critical process alone, defense in depth means layered controls, and job rotation means periodically changing responsibilities to detect abuse.

Score: · Hundreds more with explanations, free in the app: Get CertOwl on the App Store

Frequently asked questions

Which Security+ domain is the hardest?

Reports differ by background. Technical candidates usually struggle most with Program Management and Oversight, while career changers find Security Operations heaviest because it rewards hands-on familiarity.

Do the domain percentages match the number of questions I will see?

Only approximately. Forms differ, some questions are unscored experiments, and PBQs blur the count further, so treat the weights as study guidance rather than a question budget.

Where do I find the official domain list?

In the free SY0-701 exam objectives PDF on CompTIA's site. It lists every domain, objective and example topic, and it is the single most useful download of your preparation.

CertOwl drills all five Security+ domains with scenario questions that explain every answer, tracks your readiness per domain so you can see the weak one coming, and brings your misses back through spaced repetition. The A+ and Network+ tracks are completely free.

Get CertOwl on the App Store

Free download · A+ and Network+ completely free
+ daily lessons, flashcards and full exam simulations

More CompTIA guides